CVE-2026-42523
CVE-2026-42523
9.0
CriticalPublished:
Last updated:
Source:jenkinsci-cert@googlegroups.com
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- Required
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
References
jenkinsci-cert@googlegroups.com
https://www.jenkins.io/security/advisory/2026-04-29/#SECURITY-3704